Technical information
Voice Messaging Systems
6-12 Issue 7 June 2001
See ‘‘Security Tips’’ on page 6-3 for additional ways to detect voice mail fraud.
NOTE:
The System Administrator can also view a logfile to see if a mailbox is being
hacked. For the AUDIX Voice Mail System R1, the administrator can view
the logfile by typing
system:log:display. For the DEFINITY AUDIX and
Avaya I
NTUITY Voice Mail Systems, the administrator can view the logfile by
typing
display administration-log.
Call Detail Recording (CDR) / Station Message
Detail Recording (SMDR)
With Call Detail Recording activated for the incoming trunk groups, you can check
the calls into your voice mail ports. A series of short holding times may indicate
repeated attempts to enter voice mailbox passwords. See also ‘‘Security Violation
Notification Feature (DEFINITY ECS and DEFINITY G3 only)’’ on page 4-57.
NOTE:
Most call accounting packages discard this valuable security information. If
you are using a call accounting package, check to see if this information can
be stored by making adjustments in the software. If it cannot be stored, be
sure to check the raw data supplied by the CDR.
Review CDR for the following symptoms of voice mail abuse:
Short holding times on any trunk group where voice mail is the originating
endpoint or terminating endpoint
Calls to international locations not normal for your business
Calls to suspicious destinations
Numerous calls to the same number
Undefined account codes
NOTE:
For DEFINITY G2 and System 85, since CDR only records the last
extension on the call, internal toll abusers transfer unauthorized calls to
another extension before they disconnect so that the CDR does not track
the originating station. If the transfer is to your voice mail system, it could
give a false indication that your voice mail system is the source of the toll
fraud.
For DEFINITY ECS, DEFINITY G1, G3, and System 75:
To display the Features-Related System Parameters screen, use the
change system-parameters feature (G1 and System 75 only) or the
change system-parameters cdr feature (G3 only).
NOTE:
Also using direct TACs on some SMDRs/CDRs can result in the
non-recording of fraudulent calls.